Impact
In the Linux kernel, the ath6kl driver performs a subtraction of fixed IE offsets from the association request and response. Because no lower bound is checked, an underflow can occur, wrapping the value to a large number. The resulting over‑read copies data from adjacent slab memory into a user‑space buffer via nl80211, exposing sensitive information without any privilege escalation.
Affected Systems
The vulnerability exists in ath6kl co‑processor driver changes. Any distribution running a kernel with the unpatched ath6kl code is susceptible; no specific kernel versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 8.1 signifies a high severity. The EPSS score of < 1% indicates a very low likelihood of exploitation, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is sending malformed association frames from an attacker‑controlled Wi‑Fi access point to the device, a scenario that is feasible over the air. Successful exploitation results in leaking adjacent memory contents to the device user, which could aid further attacks.
OpenCVE Enrichment
Debian DSA